EBA, EIOPA and ESMA's Autumn 2026 Risk Update, Published 23 September 2026, Warns That Quantum Attacks on Bank and Blockchain Cryptography Could Arrive Before Quantum Profits Do

Board-ready intelligence on quantum innovation · Biomedical discovery · Post-quantum transition
The three European Supervisory Authorities name quantum computing in their joint risk update as a threat to the cryptography under payments, databases and blockchains. Here is what the 19-slide document says, what DORA already requires and what the EU post-quantum roadmap recommends, and what the recommendations leave out.

Post-Quantum Transition

The three European Supervisory Authorities name quantum computing in their joint risk update as a threat to the cryptography under payments, databases and blockchains. Here is what the 19-slide document says, what DORA already requires and what the EU post-quantum roadmap recommends, and what the recommendations leave out.

Published by Quentir Systems LLC · September 23, 2026 · 7 min read

On 8 April 1998, at a round table held at the Bank for International Settlements, the Basle Committee on Banking Supervision, the Committee on Payment and Settlement Systems, the International Association of Insurance Supervisors and IOSCO agreed to establish a Joint Year 2000 Council to coordinate one engineering problem across the world's financial system. The date-change fault in old software had three properties that made supervisors nervous: it touched every institution at once, it sat inside systems that many firms first had to inventory before they could fix, and it had a fixed deadline of 1 January 2000. Supervisors could plan backwards from that date, and they did.

The European Supervisory Authorities have now written about a cousin of that problem, and in Quentir's reading it is one without a fixed date. On 23 September 2026 the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority published their Autumn 2026 risk update, and one slide of it treats quantum computing as a threat to the cryptography under Europe's payments, records and blockchains. The sentence that matters most is short: the threats "could materialise earlier than any viable commercial application."

Practical takeaway. The three EU financial supervisors now say in a joint risk document that the cryptographic downside of quantum computing may arrive before its commercial upside. They connect it to DORA's cryptography duty and to the EU roadmap's recommended end-2026 start, while their recommendations so far contain no quantum-specific supervisory action.

What EBA, EIOPA and ESMA published on 23 September 2026, and who it was written for

The document is JC 2026 29, the Joint Committee Update on Risks and Vulnerabilities in the EU Financial System, Autumn 2026, a 19-slide presentation. Its audience is finance ministries and central banks: its findings were presented on 10 September 2026 to the Financial Stability Table of the EU's Economic and Financial Committee, where national treasuries and central bankers meet, and released two weeks later with a press statement.

Its headline themes are elsewhere. The ESAs describe a resilient financial system, with EU equities at record highs, banks profitable and well capitalised, and insurers holding strong fundamentals. The concerns they single out are reliance on non-EU providers and infrastructure, cyber risk sharpened by increasingly capable AI models, and the fast growth of private credit. Quantum computing sits inside the second of those, on the slide titled "Cyber Risks, Frontier AI models and Quantum Computing."

What slide 17 of the Autumn 2026 update says about quantum computing and cryptography

The slide's own subheading reads "Quantum computing offers opportunities, but potential threats warrant early system upgrades." Beneath it sit six claims, each worth reading in its own words. Quantum computing could transform the financial sector with benefits in the medium term, for example in optimising financial processes, fraud and compliance monitoring, pricing and simulation. An advanced quantum computer could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains. Threats could materialise earlier than any viable commercial application. Information gathered now could be decrypted in the future, the pattern known as harvest now, decrypt later. DORA requires financial entities to adopt state-of-the-art cryptography against new threats. And the EU NIS Cooperation Group recommended that Member States adopt a post-quantum migration strategy by the end of 2026.

The third claim changes the others. A supervisor that expects benefits and risks to arrive together can wait for the market to mature and regulate the mature market. The ESAs say the dangerous capability may come first, which means the defensive work cannot be timed to the commercial cycle. The press release repeats the point in almost the same words: the risks "could also materialise faster than any commercially viable application." Quentir has followed the collection side of that logic before, in the analysis of a task force built for ciphertext already on deposit; the ESAs have now put the same mechanism into a joint financial-stability document.

Why the ESAs placed quantum risk next to frontier AI and non-EU technology providers

The placement is deliberate. The quantum slide shares a page with the finding that frontier AI models can identify and exploit IT weaknesses at unprecedented speed, including previously unknown vulnerabilities, and it follows the report's main theme: Europe's financial sector depends heavily on ICT service providers, payment systems and market infrastructure outside the European Economic Area. On 31 July 2026 the same three authorities had already called for stronger governance and consistent supervision of ICT risks from frontier AI models. The autumn update adds quantum computing to that line of thought as a second technology that can weaken a control financial institutions assume is solid.

The dependency data make the blockchain point concrete. The same report notes that only about 8 percent of crypto trades are made against the euro, compared with 40 to 50 percent against the US dollar, that euro-denominated stablecoins are under 1 percent of market value, and that no EU-headquartered exchange is in the top 15. Those figures describe where trading and exchanges sit, which is a dependency of its own. They say less about where protocol decisions are made, and for public blockchains the answer is usually a developer and node community with no home supervisor at all. Bitcoin's migration debate, which Quentir covered when the quantum upgrade found a patron, is a case in point: EU supervisors can describe the exposure of EU holders and firms; they cannot unilaterally amend Bitcoin's consensus rules.

The attack estimates behind the slide keep moving. In September 2026 Georgia Tech researchers cut the logical-qubit estimate for the quantum attack on elliptic-curve discrete logarithms to 5n/2, where n is the bit length of the curve; that problem sits behind most blockchain signatures. The ESAs cite no such papers, and the result is separate research context showing that the estimates keep falling.

What DORA requires of banks, insurers and fund managers, and what the EU post-quantum roadmap recommends

Two instruments stand behind the slide. The first is the Digital Operational Resilience Act, which has applied to banks, insurers, investment firms, fund managers and crypto-asset service providers since 17 January 2025. Its regulatory technical standard on the ICT risk management framework, Commission Delegated Regulation (EU) 2024/1774, devotes Article 6 to encryption and cryptographic controls, including provisions for updating or changing cryptographic technology, where necessary, on the basis of developments in cryptanalysis, and Article 7 to the management of cryptographic keys across their lifecycle. Those duties are risk-based: they require a firm to follow cryptanalysis and act where its own assessment says it must, and they set no quantum-specific date. The autumn update restates the point in a financial-stability document addressed to finance ministries.

The second is the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, published by the NIS Cooperation Group on 23 June 2025 in response to the Commission's Recommendation of 11 April 2024. According to the Commission's announcement, all Member States should start the transition by the end of 2026, and critical infrastructure should move to post-quantum cryptography as soon as possible and no later than the end of 2030. These are recommended horizons addressed to Member States. They are not, by themselves, statutory deadlines for any individual bank or insurer. Banking and financial market infrastructures are listed among the sectors of high criticality in Annex I of the NIS2 Directive, so national strategies written against that horizon may reach them alongside DORA.

For the people whose savings sit in these systems, the practical meaning is simple. A mortgage file, a pension record or a payment history encrypted today may still be sensitive in fifteen years. If it is collected now and decrypted later, the harm lands on a household that never chose the cipher.

How Quentir Reads It

The most useful thing in this document is the gap between its analysis and its recommendations. The analysis is clear: quantum computing threatens cryptography that finance depends on, the threat may come early, vulnerable encrypted data collected now may be decrypted later, and slide 17 says these threats warrant early system upgrades. The recommendation that carries quantum computing in its heading, "Continue to plan and prepare for the risks from the rapid development of AI and quantum computing", then lists three actions: rely on DORA and the AI Act as a foundation, maintain operational resilience and contingency planning, and strengthen software quality with practices such as AI-powered security testing. None of the three names cryptography, an inventory or a date. The criticism is confined to that closing page: DORA's 2024 standard already requires firms to follow developments in cryptanalysis, and the recommendations simply add no quantum-specific implementation step to it.

Supervisors often name a risk in a stability document before they write a more detailed expectation about it, so the gap may close. In Quentir's reading, the Y2K comparison shows what is missing: what made Y2K governable was a date to plan backwards from. The ESAs' own words say only that the attacker's timetable may be shorter than the market's. The EU roadmap supplies the nearest substitute: a start by the end of 2026 and critical infrastructure by the end of 2030. Those dates offer a planning reference; readiness will depend on each institution's exposures, implementation and subsequent supervisory expectations.

For institutions that want that planning horizon turned into a working plan, the Signature Report, the PQC Migration Roadmap, adds what a public analysis cannot: a fixed scope, an executive summary, a phased checklist, refresh triggers and a dated source spine, licensed for internal use.

The next Joint Committee update will show whether this slide was a mention or the start of a supervisory line. The signs to look for are a quantum-specific expectation under DORA, a request for cryptographic inventories in supervisory reporting, or a reference to the 2030 horizon in the ESAs' own recommendations. Any one of them would move quantum risk from the analysis pages into the recommendations.

Sources: European Banking Authority, "ESAs call for vigilance over external dependencies, cyber threats and private credit risks" (press release, 23 September 2026), for the publication date, the 10 September 2026 presentation to the Financial Stability Table of the Economic and Financial Committee, the resilience findings and the quoted sentence that risks "could also materialise faster than any commercially viable application"; Joint Committee of the ESAs, Joint Committee Update on Risks and Vulnerabilities in the EU Financial System, Autumn 2026, JC 2026 29 (PDF, ESMA copy, 23 September 2026), for the slide on cyber risks, frontier AI models and quantum computing, the harvest-now-decrypt-later, DORA and NIS Cooperation Group bullets, the crypto-market dependency figures, and the policy recommendations; EIOPA, "EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector" (31 July 2026); European Commission, "A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography" (23 June 2025) and "EU reinforces its cybersecurity with post-quantum cryptography" (23 June 2025), for the end-2026 start and end-2030 critical-infrastructure dates; Commission Delegated Regulation (EU) 2024/1774 (regulatory technical standards on the ICT risk management framework under Regulation (EU) 2022/2554, DORA), Articles 6 and 7. Bank for International Settlements, "Joint Year 2000 Council" (media release, 19 May 1998), for the 8 April 1998 agreement and the four sponsoring committees. Public sources checked 23 September 2026.

Published intelligence, built to inform your own decisions. Published: September 23, 2026.

© 2026 Quentir Systems LLC
Next
Next

British Columbia and School District 59 Sued OpenAI and Sam Altman on 21 September 2026 Over a ChatGPT Account Flagged in June 2025 and Not Reported to Police Before the Attack